High priority
SAP security note 1598819, "Directory traversal in RPUQSTC0", is a program error note released on 10.01.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
RPUQSTC0 contains a directory traversal vulnerability that allows a malicious user to write arbitrary files on the remote server. This can lead to data corruption or alteration of system behavior.
Solution
To address this vulnerability, you have two options:
- Import the relevant HR Support Package specified for your release. You can find the necessary support packages here.
- Implement the relevant correction instructions provided in the note. Details for the correction instructions can be accessed here for SAP_HRCCH and here for SAP_HR.
References
- 1533573 – Documentation: Withholding tax scales Geneva
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- SAP_HR (46C)
- SAP_HRCCH (470, 500, 600, 604)
Full note on SAP: SAP Support Launchpad note 1598819
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
